Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8cv-g4gv-cx2g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

EPSS

Процентиль: 97%
0.39871
Средний

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

CVSS3: 8.1
nvd
больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

CVSS3: 8.1
debian
больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. T ...

EPSS

Процентиль: 97%
0.39871
Средний